Korean
<< Back
VID 26357
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The hotfix (MS08-041, 955617) for 'Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access' has not been applied. Microsoft Snapshot Viewer is a viewer for snapshots created with Microsoft Access. Snapshot Viewer is available as an ActiveX control, which is provided by snapview.ocx, or as a stand-alone application. The Microsoft Office Snapshot Viewer ActiveX control contains a race condition, which can allow a remote, unauthenticated attacker to download arbitrary files to arbitrary locations. By convincing a victim to view an HTML document (web page, HTML email, or email attachment), a remote attacker could download files and execute arbitrary code on a vulnerable system within the security context of the user running IE.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.microsoft.com/technet/security/bulletin/ms08-041.mspx
http://www.microsoft.com/technet/security/advisory/955179.mspx
http://www.frsirt.com/english/advisories/2008/2012
http://www.kb.cert.org/vuls/id/837785
http://www.securitytracker.com/id?1020433
http://secunia.com/advisories/30883

* Platforms Affected:
Microsoft Access 2000 SP3
Microsoft Access 2002 SP3
Microsoft Access 2003 SP3
Microsoft Access 2003 SP2
Microsoft Snapshot Viewer
Microsoft Windows Any version
Recommendation Apply the appropriate patch (955617) for your system, as listed in Microsoft Security Bulletin MS08-041 at http://www.microsoft.com/technet/security/bulletin/ms08-041.mspx

-- OR --

Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com . Windows Update detects what version of Windows you are running and offers the appropriate patch.
Related URL CVE-2008-2463 (CVE)
Related URL 30114 (SecurityFocus)
Related URL 43613 (ISS)